<CodeExam/>

codeexam.ai  ·  github.com/aschulman42-cell/code-exam

// overview

CodeExam

A tool for examining code — source code, and quasi-source: recovering indexable structure from minified bundles, binaries, and embedded scripts. Browse, search, and cross-reference at scale. Deterministic engine, optional AI layer.

Use CodeExam to first build an index over a codebase, then browse, search, and cross-reference — callers, callees, call trees, file/folder coupling — at scale, across C, C++, Java, JavaScript, TypeScript, Python, C#, Go, Rust, PHP, and Ruby (tree-sitter), with regex-level support for a dozen more.

CodeExam represents the principal author's several decades of experience as a source-code examiner in litigation and in reverse-engineering commercial software. It was built initially for source-code examination in patent and trade-secret litigation, but most of what it does is general-purpose code comprehension — useful to anyone facing a large, unfamiliar codebase they didn't write.

The engine is deterministic: the same index and the same command produce the same answer, with no AI model in the basic loop. An optional set of AI-based features can summarize code, answer questions, and draft analyses — running against a cloud model (Claude, ChatGPT, or Gemini) or, for code that must not leave a protected machine, a local GGUF model, fully air-gapped.

Key Features

01AI-assisted examination

An optional set of AI-based features — a cloud model (Claude, ChatGPT, or Gemini), or a local GGUF model on your own GPU — together with CodeExam's MCP tools, to summarize code, answer questions, and draft analyses. CodeExam's emphasis is on running AI over its own deterministic index, and on the local option.

02Air-gapped operation

CodeExam can run with all internet and cloud access blocked — for code that must not leave a protected machine. Even fully air-gapped, you still have the option of AI features by pointing it at a local GGUF model. Local first is a key underlying premise.

03Uncovering what a codebase is about

CodeExam extracts a codebase's vocabulary and key concepts, its breadcrumbs (telemetry markers in code), and metrics — and presents initial questions to ask and good first places to look, via the Overview and optional AI Overview features.

04Quasi-source

A surprising amount of indexable structure can be recovered from artifacts never shipped as source — minified and bundled JS, binaries (strings and demangled C++ symbols), JavaScript embedded inside native executables — then searched and cross-referenced with the same machinery as real source.

05Detecting AI/ML and infrastructure in target code

A detector suite surfaces inferred AI/ML pipelines, the models a codebase defines and uses, LLM calls, tools, agents and chains, embeddings, prompts, and the operational stack (e.g. containers).

06Structural (non-textual) code search

Ways of finding and identifying code that don't depend on what the code says: structural duplicate detection and diff, transform-resilient function fingerprints, synonym expansion in Multisect search, and catalogs that link commands to their handlers by position in dispatch tables rather than by name.

What CodeExam Is Good At

Orienting fast in unfamiliar code

Vocabulary and Overview tell you what a codebase is about and where to look first, before you read a line.

Helping to prove an absence

Corpus-wide negative search: helping show something is not present anywhere in the index, not just that it's missing from the file you happened to open.

Examining what wasn't shipped as source

Quasi-source recovers structure from minified bundles and binaries.

Seeing what the code points to but doesn't contain

Surfaces the external surface: URLs and hosts, env vars, file paths, external commands, cloud config, and model IDs — including files the code references but that aren't in the index.

Working on technical prose, not just code

Searching and charting patent claims against a codebase, and generating pseudo-claims from code: claim-shaped descriptions of what the code does.

Multisect search

Narrowing a multi-term search to the smallest scope in which all the terms co-occur, from file, to function, to the specific lines.

Helping map the client/server boundary

Finds declared server routes and the client calls that consume them, reconciled by URL path, and flags client calls with no matching server route — the missing server code signal.

// about

Built at the Intersection of Code and Law

CodeExam grew out of years of software litigation consulting work — the need for a rigorous, defensible, and confidential tool for examining source code in legal disputes.

Why CodeExam Exists

Software disputes — trade secret misappropriation, copyright infringement, patent claims involving code — require a level of technical analysis that most litigation tools were never designed to support. Attorneys need expert-ready output. Experts need reproducible, traceable methodology. And everyone involved needs to know that confidential source code subject to protective orders stays confidential.

CodeExam was built to fill that gap. It started as a set of internal analysis scripts used in actual litigation engagements, and evolved into a structured tool with a consistent interface, local AI inference, and output designed to survive cross-examination.

CodeExam was developed by Andrew Schulman of SoftwareLitigationConsulting.com, who provided software expert witness and litigation support services since the early 1990s, and who co-authored the well-known reverse-engineering books Undocumented DOS and Undocumented Windows.

SoftwareLitigationConsulting.com

CodeExam is related to Software Litigation Consulting, which was handled expert witness engagements, source code review, and litigation support for attorneys in IP, trade secret, and software-related disputes. CodeExam formalizes and extends the analytical methods used in those engagements into a repeatable, auditable tool.

Expert Witness Background

Software Expert Witness

Retained primarily as a consulting non-testifying source-code examiner in federal and state court proceedings involving source code, software architecture, and technical IP disputes.

Source Code Review

Conducted forensic-level source code review in trade secret misappropriation cases, copyright infringement claims, and software licensing disputes.

Litigation Support

Provided technical analysis, expert reports and draft reports, and deposition support to plaintiff and defense counsel in complex software litigation matters.

Local AI Research

Developed and tested local AI inference pipelines for code analysis, with a focus on maintaining confidentiality requirements imposed by court protective orders.

// features

What CodeExam Analyzes

A structured examination engine built for the evidentiary standards of software litigation — not general-purpose code review.

// source code

Source Code Analysis

CodeExam examines traditional source code — C, C++, Java, Python, JavaScript, TypeScript, Go, Rust, and more. It identifies structural similarities, shared logic patterns, copied functions, and common algorithmic approaches between two codebases, producing findings with file-level and line-level attribution suitable for expert reports.

  • Multi-language support across compiled and interpreted languages
  • Function-level and block-level similarity detection
  • File dependency mapping and architectural comparison
  • Line-attributed findings with exhibit-ready output
// quasi-source code

Quasi-Source Code

Not all code in litigation is clean source. CodeExam handles quasi-source code — decompiled bytecode, disassembled binaries, minified JavaScript, obfuscated output, and intermediate representations. These forms appear frequently in trade secret and copyright cases where the original source is unavailable or disputed.

  • Decompiled Java bytecode (.class files)
  • Disassembled native binaries
  • Minified and bundled JavaScript
  • Obfuscated code with identifier normalization
  • Intermediate representations (LLVM IR, JVM bytecode)
// local ai

Local AI Inference

CodeExam runs AI analysis entirely on your machine using local models — no cloud API calls, no data transmission, no third-party servers. Models including Gemma 3, CodeLlama, and DeepSeek Coder run via Ollama or llama.cpp. This architecture is specifically designed to satisfy confidentiality obligations under court protective orders.

  • Gemma 3 (Google, fully local)
  • CodeLlama 7B / 13B / 34B (Meta)
  • DeepSeek Coder (DeepSeek AI)
  • Ollama and llama.cpp backends supported
  • No internet connection required during analysis
  • Model selection configurable per engagement
// confidentiality

Confidentiality by Architecture

Confidential source code in litigation is typically subject to protective orders that restrict how it can be handled, transmitted, and stored. CodeExam's local-only architecture means the code never leaves the machine running the analysis. There is no cloud endpoint, no telemetry, no usage logging, and no data retention outside the analyst's own environment.

  • Zero outbound network calls during analysis
  • No telemetry or usage reporting
  • No cloud model API dependencies
  • Runs air-gapped if required
  • Audit log stays local to the analyst's machine
// output

Litigation-Ready Output

Findings are structured for use in expert reports, declarations, and deposition preparation. Each finding includes source attribution, similarity scoring, methodology notes, and exhibit references. Output formats are designed to be reproducible — the same inputs produce the same findings, which is essential for withstanding cross-examination on methodology.

  • Structured JSON and human-readable report formats
  • Per-finding similarity scores with methodology notes
  • Exhibit-numbered file references
  • Reproducible results from identical inputs
  • Expert report integration templates

codeexam.ai  ·  Andrew Schulman  ·  undoc at sonic dot net  ·  SoftwareLitigationConsulting.com